Vulnerability Name:

CVE-2012-1721 (CCN-76240)

Assigned:2012-06-12
Published:2012-06-12
Updated:2022-05-13
Summary:Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-1722.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-1721

Source: SUSE
Type: UNKNOWN
SUSE-SU-2012:1231

Source: SUSE
Type: UNKNOWN
SUSE-SU-2012:1265

Source: HP
Type: UNKNOWN
SSRT100919

Source: CCN
Type: RHSA-2012-0734
Critical: java-1.6.0-sun security update

Source: REDHAT
Type: UNKNOWN
RHSA-2012:0734

Source: CCN
Type: RHSA-2012-1019
Critical: java-1.7.0-oracle security update

Source: CCN
Type: RHSA-2012-1238
Critical: java-1.6.0-ibm security update

Source: CCN
Type: RHSA-2012-1289
Critical: java-1.7.0-ibm security update

Source: CCN
Type: RHSA-2013-1455
Low: Red Hat Network Satellite server IBM Java Runtime security update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:1455

Source: CCN
Type: RHSA-2013-1456
Low: Red Hat Network Satellite server IBM Java Runtime security update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:1456

Source: CCN
Type: SA49472
Oracle Java Multiple Vulnerabilities

Source: CCN
Type: SA49542
Apple Mac OS X update for Java

Source: CCN
Type: SA50607
IBM Java 7 Multiple Vulnerabilities

Source: CCN
Type: SA53006
IBM Tivoli System Automation Application Manager Multiple Vulnerabilities

Source: CCN
Type: Apple KB HT5319
About the security content of Java for OS X 2012-004 and Java for Mac OS X 10.6 Update 9

Source: CCN
Type: IBM Security Bulletin 1632668
IBM Tivoli System Automation for Multiplatforms

Source: CCN
Type: IBM Security Bulletin 1633991
Tivoli System Automation Application Manager 3.2.2

Source: CCN
Type: IBM Security Bulletin 1650822
Java Security Vulnerabilitys addressed in IBM Tivoli Netcool OMNIbus

Source: CCN
Type: IBM Security Alerts
Oracle August 2012 Security Alert

Source: CCN
Type: Oracle Java SE Critical Patch Update Advisory - June 2012
Oracle Java SE Critical Patch Update Advisory - June 2012

Source: CONFIRM
Type: Vendor Advisory
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html

Source: CCN
Type: OSVDB ID: 82875
Oracle Java SE / JRE Deployment Sub-component Unspecified Remote Code Execution (2012-1721)

Source: BID
Type: UNKNOWN
53959

Source: CCN
Type: BID-53959
Oracle Java SE CVE-2012-1721 Remote Code Execution Vulnerability

Source: XF
Type: UNKNOWN
javase-jre-cve20121721(76240)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:16358

Source: CCN
Type: ZDI-12-189
Oracle Java WebStart Changing System Properties Remote Code Execution Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:jre:*:update4:*:*:*:*:*:* (Version <= 1.7.0)
  • OR cpe:/a:oracle:jdk:*:update4:*:*:*:*:*:* (Version <= 1.7.0)

  • Configuration 2:
  • cpe:/a:oracle:jdk:*:update32:*:*:*:*:*:* (Version <= 1.6.0)
  • OR cpe:/a:oracle:jre:*:update32:*:*:*:*:*:* (Version <= 1.6.0)

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras:5:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_extras:6:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
  • OR cpe:/a:oracle:jdk:1.7.0:update4:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:tivoli_netcool/omnibus:7.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:java:7.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/omnibus:7.3.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/omnibus:7.4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7729
    P
    p7zip-16.02-150200.14.9.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7707
    P
    libykcs11-1-1.6.2-4.30 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:42330
    P
    Security update for mokutil (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:42329
    P
    Security update for dwarves and elfutils (Moderate)
    2022-08-01
    oval:org.opensuse.security:def:20121721
    V
    CVE-2012-1721
    2022-05-20
    oval:org.opensuse.security:def:31756
    P
    Security update for apache2 (Important)
    2022-01-12
    oval:org.opensuse.security:def:7005
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 15 SP1) (Important)
    2021-12-14
    oval:org.opensuse.security:def:31700
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:31699
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:32210
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:32209
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:26151
    P
    Security update for python3 (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:26152
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:6980
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP1) (Important)
    2021-10-14
    oval:org.opensuse.security:def:32166
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:32165
    P
    Security update for cpio (Important)
    2021-08-23
    oval:org.opensuse.security:def:26103
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:26102
    P
    Security update for php72 (Important)
    2021-08-06
    oval:org.opensuse.security:def:32143
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-07-21
    oval:org.opensuse.security:def:32144
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-07-21
    oval:org.opensuse.security:def:36537
    P
    perl-base-32bit-5.10.0-64.72.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36495
    P
    libtirpc-devel-0.2.1-1.7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32104
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:32105
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:6905
    P
    Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP1) (Important)
    2021-05-25
    oval:org.opensuse.security:def:26050
    P
    Security update for python3 (Important)
    2021-05-17
    oval:org.opensuse.security:def:26049
    P
    Security update for lz4 (Important)
    2021-05-14
    oval:org.opensuse.security:def:46358
    P
    java-1_6_0-ibm-1.6.0_sr16.1-5.9 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:13238
    P
    java-1_6_0-ibm-1.6.0_sr16.1-5.9 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:6886
    P
    Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP1) (Important)
    2021-04-28
    oval:org.opensuse.security:def:31608
    P
    Security update for xen (Important)
    2021-04-19
    oval:org.opensuse.security:def:31607
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:7069
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP2) (Important)
    2021-04-07
    oval:org.opensuse.security:def:6871
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 15 SP1) (Important)
    2021-04-07
    oval:org.opensuse.security:def:26205
    P
    Security update for openssl-1_0_0 (Moderate)
    2021-03-08
    oval:org.opensuse.security:def:26204
    P
    Security update for freeradius-server (Low)
    2021-03-04
    oval:org.opensuse.security:def:26191
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:26190
    P
    Security update for MozillaFirefox (Low)
    2021-02-10
    oval:org.opensuse.security:def:7056
    P
    Security update for the Linux Kernel (Important)
    2020-12-10
    oval:org.opensuse.security:def:35746
    P
    libfreebl3-3.13.1-0.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35923
    P
    java-1_7_0-ibm-1.7.0_sr4.1-0.5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35857
    P
    PackageKit-0.3.14-2.28.46 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35697
    P
    findutils-4.4.0-38.26.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35813
    P
    python-sssd-config-1.5.11-0.9.96 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35638
    P
    squid-2.7.STABLE5-2.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35785
    P
    mono-core-2.6.7-0.7.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35922
    P
    java-1_6_0-ibm-1.6.0_sr13.1-0.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:32000
    P
    Security update for python-setuptools (Important)
    2020-12-02
    oval:org.opensuse.security:def:34998
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:31757
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:6824
    P
    python-libxml2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32056
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26921
    P
    java-1_6_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25549
    P
    Security update for tigervnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:31999
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:25484
    P
    Security update for libqt4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6748
    P
    libqt4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25815
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25757
    P
    Security update for flash-player (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7038
    P
    libgadu3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32887
    P
    java-1_7_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35094
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:32847
    P
    dbus-1-glib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31402
    P
    Security update for perl-DBD-mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25474
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:35388
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26922
    P
    java-1_7_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6778
    P
    libvte9 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26886
    P
    ecryptfs-utils-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25485
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:31843
    P
    Security update for cairo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31389
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25758
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25676
    P
    Security update for postgresql, postgresql96, postgresql10 and postgresql12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32848
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35010
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31391
    P
    Security update for pam (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25898
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25472
    P
    Security update for apache2-mod_perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35331
    P
    Security update for minicom (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31475
    P
    Security update for procps (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26887
    P
    ed on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6756
    P
    libsndfile1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31844
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:26248
    P
    Security update for freerdp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31390
    P
    Security update for pam
    2020-12-01
    oval:org.opensuse.security:def:25677
    P
    Security update for raptor (Important)
    2020-12-01
    oval:org.opensuse.security:def:32055
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25548
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:34999
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:25899
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25473
    P
    Security update for strongswan (Important)
    2020-12-01
    oval:org.opensuse.security:def:25814
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:7047
    P
    libhogweed2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35230
    P
    Security update for libmspack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32886
    P
    java-1_6_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31476
    P
    Security update for puppet
    2020-12-01
    oval:org.opensuse.security:def:31401
    P
    Security update for perl-DBD-mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35478
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26249
    P
    Security update for libtomcrypt (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:19858
    V
    HP-UX Running Java, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
    2015-04-20
    oval:org.mitre.oval:def:21447
    P
    RHSA-2012:1238: java-1.6.0-ibm security update (Critical)
    2015-03-09
    oval:org.mitre.oval:def:23844
    P
    ELSA-2012:1019: java-1.7.0-oracle security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:23195
    P
    ELSA-2012:0734: java-1.6.0-sun security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:23688
    P
    ELSA-2012:1238: java-1.6.0-ibm security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:23797
    P
    ELSA-2012:1289: java-1.7.0-ibm security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:20996
    P
    RHSA-2012:1019: java-1.7.0-oracle security update (Critical)
    2014-02-24
    oval:org.mitre.oval:def:21403
    P
    RHSA-2012:0734: java-1.6.0-sun security update (Critical)
    2014-02-24
    oval:org.mitre.oval:def:21607
    P
    RHSA-2012:1289: java-1.7.0-ibm security update (Critical)
    2014-02-24
    oval:org.mitre.oval:def:16358
    V
    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE (subcomponent: Deployment) 7 update 4 and earlier, and 6 update 32 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-1722.
    2013-06-10
    oval:com.redhat.rhsa:def:20121289
    P
    RHSA-2012:1289: java-1.7.0-ibm security update (Critical)
    2012-09-18
    oval:com.redhat.rhsa:def:20121238
    P
    RHSA-2012:1238: java-1.6.0-ibm security update (Critical)
    2012-09-06
    oval:com.redhat.rhsa:def:20121019
    P
    RHSA-2012:1019: java-1.7.0-oracle security update (Critical)
    2012-06-20
    oval:com.ubuntu.precise:def:20121721000
    V
    CVE-2012-1721 on Ubuntu 12.04 LTS (precise) - low.
    2012-06-16
    oval:com.redhat.rhsa:def:20120734
    P
    RHSA-2012:0734: java-1.6.0-sun security update (Critical)
    2012-06-13
    BACK
    oracle jre * update4
    oracle jdk * update4
    oracle jdk * update32
    oracle jre * update32
    oracle jre 1.7.0 update4
    oracle jdk 1.7.0 update4
    ibm tivoli netcool/omnibus 7.3.0
    ibm java 7.0.0.0
    ibm tivoli netcool/omnibus 7.3.1.0
    ibm tivoli netcool/omnibus 7.4.0